You are on page 1of 27

date/time

: 2013-04-07, 10:01:02, 546ms


computer name
: ILIE-PC
user name
: ilie <admin>
registered owner : ilie
operating system : Windows NT New build 7600
system language : English
system up time
: 3 hours 1 minute
program up time : 38 minutes 25 seconds
processor
: AMD Sempron(tm) Processor 3600+
physical memory : 688/1023 MB (free/total)
free disk space : (C:) 462.36 MB (D:) 30.15 GB
display mode
: 1280x1024, 32 bit
process id
: $4a0
allocated memory : 64.86 MB
command line
: "D:\ATI.ACE\BSplayerPro\bsplayer.exe" "D:\fylme\nevazute\Sni
tch.2013.CAM.XVID-SKA\ska-snitch-xvid.avi"
executable
: bsplayer.exe
exec. date/time : 2010-11-30 04:55
version
: 2.5.7.1049
compiled with
: Delphi 7
madExcept version : 3.0h
callstack crc
: $3216747f, $b4a30bf0, $b4a30bf0
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 0057A452 in module 'bsplayer.exe
'. Read of address 00000190.
main thread ($a50):
0057a452 +0006 bsplayer.exe
0062b872 +0012 bsplayer.exe
006543bf +0acf bsplayer.exe
004931db +000f bsplayer.exe
004930bf +002b bsplayer.exe
0047d778 +0014 bsplayer.exe
77503573 +000a USER32.dll
004df0a3 +0083 bsplayer.exe
004df0da +000a bsplayer.exe
004df2fa +0096 bsplayer.exe
006b3c8d +1201 bsplayer.exe
762e1192 +0010 kernel32.dll

bsLabel
274 +1 TbsLabelW.SetSText2
fsfrmu
235 +1 TfsOSF.SetStatText
mbsplayu 7811 +228 TMBSPlayer.mtmrTimer
ExtCtrls
TTimer.Timer
ExtCtrls
TTimer.WndProc
Classes 31881 +0 StdWndProc
DispatchMessageA
Forms
TApplication.ProcessMessage
Forms
TApplication.HandleMessage
Forms
TApplication.Run
bsplayer 653 +416 initialization
BaseThreadInitThunk

thread $310:
77605e4a +0a ntdll.dll
NtWaitForMultipleObjects
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $628:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $160:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $e20:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $93c:
77605d6a +0a ntdll.dll
775de9bb +3c ntdll.dll

NtTraceControl
EtwpNotificationThread

762e1192 +10 kernel32.dll BaseThreadInitThunk


thread $f48:
77508fbd +26 USER32.dll
GetMessageW
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $f50:
77605e6a +0a
757b1796 +66
762deffe +3e
762defad +0d
762e1192 +10

<priority:15>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForSingleObject
WaitForSingleObjectEx
WaitForSingleObjectEx
WaitForSingleObject
BaseThreadInitThunk

thread $a34:
77508fbd +26 USER32.dll
GetMessageW
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $6c0:
77605e4a +0a
757b686c +00
762df145 +89
762df2bd +13
762e1192 +10

ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

thread $950:
7760570a +000a
757bf243 +46f5
762ddaf8 +004f
762e1192 +0010

ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk
NtReadFile
ReadFile
ReadFile
BaseThreadInitThunk

thread $9d0:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $e1c:
77605e4a +0a
757b686c +00
762df145 +89
762df2bd +13
762e1192 +10

<priority:15>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $d78:
77508fbd +26 USER32.dll
GetMessageW
762e1192 +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 bsplayer.exe
00c30000 oldskin.dll
035e0000 FLVSplitter.ax
Splayer\Flash Video (FLV)
037c0000 wdmaud.drv
03800000 ksuser.dll
03920000 RealMediaSplitter.ax
Splayer\RealMedia splitter
039f0000 mkunicode.dll
Splayer\Haali media splitter
03a00000 AUDIOSES.DLL
04c20000 mkzlib.dll
Splayer\Haali media splitter
064c0000 bsrendv2.dll

2.5.7.1049
1.0.0.5

D:\ATI.ACE\BSplayerPro
D:\ATI.ACE\BSplayerPro\plugins
C:\Users\ilie\AppData\Roaming\B

6.1.7600.16385
6.1.7600.16385
1.0.1.2

C:\Windows\system32
C:\Windows\system32
C:\Users\ilie\AppData\Roaming\B
C:\Users\ilie\AppData\Roaming\B

6.1.7600.16385

C:\Windows\system32
C:\Users\ilie\AppData\Roaming\B

2.0.0.0

D:\ATI.ACE\BSplayerPro

066e0000 splitter.ax
Splayer\Haali media splitter
06770000 mkx.dll
Splayer\Haali media splitter
075b0000 ff_libfaad2.dll
Splayer\FFDShow
07640000 ffdshow.ax
Splayer\FFDShow
07e70000 NeVideo.ax
head\DSFilter
10000000 mmkeybsupp.dll
6b2e0000 ac3filter_intl.dll
Splayer\AC3 Filter
6b3e0000 ddraw.dll
6ba50000 pnrpnsp.dll
6ba70000 napinsp.dll
6bdf0000 D3DIM700.DLL
6bee0000 winrnr.dll
6bf00000 DSOUND.DLL
6c1d0000 MSVCP60.dll
6df90000 olepro32.dll
6e910000 rasadhlp.dll
6eb80000 DCIMAN32.dll
70990000 ntshrui.dll
70a00000 msi.dll
70c80000 ac3filter.ax
Splayer\AC3 Filter
70d50000 quartz.dll
70f00000 DINPUT.dll
71010000 cscui.dll
71080000 EhStorShell.dll
710c0000 ashShell.dll
710f0000 explorerframe.dll
71260000 perfos.dll
71270000 DShowRdpFilter.dll
712b0000 msdmo.dll
712c0000 devenum.dll
712e0000 CSCAPI.dll
712f0000 CSCDLL.dll
71350000 wsock32.dll
71bb0000 winmm.dll
72430000 fwpuclnt.dll
72470000 winspool.drv
738a0000 msimg32.dll
73980000 WINNSI.DLL
739a0000 IPHLPAPI.DLL
73a30000 slc.dll
73af0000 NLAapi.dll
73ce0000 ntmarta.dll
73d10000 AVRT.dll
74100000 midimap.dll
74110000 MSACM32.dll
74130000 msacm32.drv
74150000 WindowsCodecs.dll
74280000 MMDevApi.dll
74310000 DUser.dll
74340000 DUI70.dll
74590000 uxtheme.dll
745d0000 propsys.dll
74710000 comctl32.dll

1.10.262.12

C:\Users\ilie\AppData\Roaming\B
C:\Users\ilie\AppData\Roaming\B
C:\Users\ilie\AppData\Roaming\B

1.0.7.3135

C:\Users\ilie\AppData\Roaming\B

1.1.7.23

C:\Program Files\Common Files\A

1.0.0.0

D:\ATI.ACE\BSplayerPro
C:\Users\ilie\AppData\Roaming\B

6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
7.0.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
5.0.7600.16385
1.6.3.0

C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Users\ilie\AppData\Roaming\B

6.6.7600.16490
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
8.0.1483.72
6.1.7600.16385
6.1.7600.16385
1.0.0.0
6.6.7600.16385
6.6.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
7.0.7600.16385
6.10.7600.16385

C:\Windows\system32
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
D:\download
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\WinSxS\x86_microsoft

.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
74b70000 POWRPROF.dll
6.1.7600.16385
C:\Windows\system32
74ba0000 version.dll
6.1.7600.16385
C:\Windows\system32
74c30000 wshtcpip.dll
6.1.7600.16385
C:\Windows\System32
74cf0000 dwmapi.dll
6.1.7600.16385
C:\Windows\system32
74d10000 wtsapi32.dll
6.1.7600.16385
C:\Windows\system32
74e40000 srvcli.dll
6.1.7600.16385
C:\Windows\system32
75090000 DNSAPI.dll
6.1.7600.16385
C:\Windows\system32
751d0000 mswsock.dll
6.1.7600.16385
C:\Windows\System32
755f0000 SspiCli.dll
6.1.7600.16385
C:\Windows\system32
75610000 apphelp.dll
6.1.7600.16481
C:\Windows\system32
75660000 CRYPTBASE.dll
6.1.7600.16385
C:\Windows\system32
756d0000 WINSTA.dll
6.1.7600.16385
C:\Windows\system32
75710000 profapi.dll
6.1.7600.16385
C:\Windows\system32
75780000 MSASN1.dll
6.1.7600.16415
C:\Windows\system32
75790000 DEVOBJ.dll
6.1.7600.16385
C:\Windows\system32
757b0000 KERNELBASE.dll
6.1.7600.16385
C:\Windows\system32
75800000 CFGMGR32.dll
6.1.7600.16385
C:\Windows\system32
75830000 CRYPT32.dll
6.1.7600.16385
C:\Windows\system32
759e0000 WINTRUST.dll
6.1.7600.16385
C:\Windows\system32
75a10000 NSI.dll
6.1.7600.16385
C:\Windows\system32
75a20000 comdlg32.dll
6.1.7600.16385
C:\Windows\system32
75aa0000 MSCTF.dll
6.1.7600.16385
C:\Windows\system32
75b70000 CLBCatQ.DLL
2001.12.8530.16385 C:\Windows\system32
75c30000 SHLWAPI.dll
6.1.7600.16385
C:\Windows\system32
75dd0000 GDI32.dll
6.1.7600.16385
C:\Windows\system32
75e80000 msvcrt.dll
7.0.7600.16385
C:\Windows\system32
75f30000 USP10.dll
1.626.7600.16385 C:\Windows\system32
75fd0000 LPK.dll
6.1.7600.16385
C:\Windows\system32
75fe0000 RPCRT4.dll
6.1.7600.16385
C:\Windows\system32
76290000 kernel32.dll
6.1.7600.16481
C:\Windows\system32
76470000 SHELL32.dll
6.1.7600.16385
C:\Windows\system32
770c0000 SETUPAPI.dll
6.1.7600.16385
C:\Windows\system32
77260000 advapi32.dll
6.1.7600.16385
C:\Windows\system32
77300000 oleaut32.dll
6.1.7600.16385
C:\Windows\system32
77390000 ole32.dll
6.1.7600.16385
C:\Windows\system32
774f0000 USER32.dll
6.1.7600.16385
C:\Windows\system32
775c0000 ntdll.dll
6.1.7600.16385
C:\Windows\SYSTEM32
77700000 WS2_32.dll
6.1.7600.16385
C:\Windows\system32
77760000 IMM32.DLL
6.1.7600.16385
C:\Windows\system32
77780000 sechost.dll
6.1.7600.16385
C:\Windows\SYSTEM32
777a0000 WLDAP32.dll
6.1.7600.16385
C:\Windows\system32
hardware:
+ Batteries
- Microsoft Composite Battery
+ Computer
- ACPI x86-based PC
+ Disk drives
- silicon -power USB Device
- WDC WD16 00AAJS-60PSA SCSI Disk Device
+ Display adapters
- ATI Radeon X1050
(driver 8.401.0.0)
- ATI Radeon X1050 Secondary
(driver 8.401.0.0)
+ DVD/CD-ROM drives
- ATAPI DVD A DH20A4P ATA Device
+ Floppy disk drives
- Floppy disk drive
+ Floppy drive controllers
- Standard floppy disk controller

+ Human Interface Devices


- USB Input Device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard Dual Channel PCI IDE Controller
+ Keyboards
- Standard PS/2 Keyboard
+ Mice and other pointing devices
- HID-compliant mouse
+ Modems
- LGE Mobile USB Modem (driver 4.9.4.0)
+ Monitors
- Generic PnP Monitor
+ Network adapters
- NVIDIA nForce 10/100 Mbps Ethernet (driver 73.3.5.0)
+ Portable Devices
- ADI_ILIE45
+ Ports (COM & LPT)
- Communications Port (COM1)
- LGE Mobile USB Serial Port (COM11) (driver 4.9.4.0)
- Printer Port (LPT1)
+ Processors
- AMD Sempron(tm) Processor 3600+
+ Sound, video and game controllers
- High Definition Audio Device
+ Storage controllers
- AYJFRFYY IDE Controller
- NVIDIA nForce Serial ATA Controller (driver 10.6.0.16)
- NVIDIA nForce Serial ATA Controller (driver 10.6.0.16)
+ Storage volume shadow copies
- Generic volume shadow copy
+ System devices
- ACPI Fan
- ACPI Fixed Feature Button
- ACPI Power Button
- ACPI Thermal Zone
- AMD Address Map Configuration
- AMD DRAM and HyperTransport(tm) Trace Mode Configuration
- AMD HyperTransport(tm) Configuration
- AMD Miscellaneous Configuration
- Composite Bus Enumerator
- Direct memory access controller
- Extended IO Bus
- File as Volume Driver
- High Definition Audio Controller
- High precision event timer
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Motherboard resources
- Motherboard resources
- Motherboard resources
- Numeric data processor
- NVIDIA nForce PCI System Management
- PCI bus
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge

- PCI standard PCI-to-PCI bridge


- PCI standard RAM Controller
- PCI standard RAM Controller
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System CMOS/real time clock
- System speaker
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Volume Manager
+ Universal Serial Bus controllers
- LGE Mobile Composite USB Device (driver 4.9.4.0)
- Standard Enhanced PCI to USB Host Controller
- Standard OpenHCD USB Host Controller
- USB Mass Storage Device
- USB Root Hub
- USB Root Hub
cpu
eax
ebx
ecx
edx
esi
edi
eip
esp
ebp

registers:
= 00000000
= 00000000
= 00000000
= 00cc9a64
= 00cc9a64
= 0012fd40
= 0057a452
= 0012fbfc
= 0012fc80

stack dump:
0012fbfc 20
0012fc0c c4
0012fc1c 40
0012fc2c 00
0012fc3c 00
0012fc4c 00
0012fc5c 00
0012fc6c 00
0012fc7c 00
0012fc8c c4
0012fc9c 40
0012fcac c4
0012fcbc 00
0012fccc 12
0012fcdc 13
0012fcec 13
0012fcfc 12
0012fd0c 11
0012fd1c 24
0012fd2c 30

5c
43
fd
00
00
00
00
00
00
30
fd
fc
00
03
01
01
03
3b
00
00

dc
65
12
00
00
00
00
00
00
49
12
12
00
0c
00
00
0c
94
00
00

01
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
1f
00
00

30
90
cc
00
00
00
00
00
ac
58
13
7a
00
13
cd
68
13
00
01
ff

00
fc
31
00
00
00
00
00
fc
fd
01
d7
00
01
ab
fd
01
fe
00
ff

d0
12
49
00
00
00
00
00
12
12
00
47
00
00
ba
12
00
12
00
ff

01
00
00
00
00
00
00
00
00
00
00
00
00
00
dc
00
00
00
00
ff

77
0c
88
00
00
30
00
00
de
2c
00
13
f0
01
00
76
01
f8
00
ff

b8
4d
85
00
00
59
00
00
31
4b
00
01
fc
00
00
88
00
fd
00
ff

62
40
df
00
00
8c
00
00
49
40
00
00
12
00
00
50
00
12
00
ff

00
00
01
00
00
9e
00
00
00
00
00
00
00
00
00
77
00
00
00
ff

50
80
00
00
00
00
00
00
b4
ac
88
01
ef
00
40
c8
00
10
00
1f

81
fc
00
00
00
00
00
00
fc
fc
85
00
86
00
fd
0f
00
92
00
88

d6
12
00
00
00
00
00
00
12
12
df
00
50
00
12
2f
00
d9
00
50

01
00
00
00
00
00
00
00
00
00
01
00
77
00
00
00
00
00
00
77

.\..0...w.b.P...
.Ce......M@.....
@....1I.........
................
................
........0Y......
................
................
.........1I.....
.0I.X...,K@.....
@...............
....z.G.........
..............Pw
................
............@...
....h...v.Pw../.
................
.;..............
$...............
0.............Pw

disassembling:
0057a44c
public bsLabel.TbsLabelW.SetSText2: ; function entry point

0057a44c 273 push


0057a44d
push
0057a44e
mov
0057a450
mov
0057a452 274 > cmp
0057a459
jz
0057a45b
mov
0057a45d
call
0057a462 275 mov
0057a464
mov
[...]

ebx
esi
esi, edx
ebx, eax
byte ptr [ebx+$190], 0
loc_57a462
eax, ebx
-$1ca ($57a298)
; bsLabel.TbsLabelW.StopScroll
edx, esi
eax, ebx

date/time
: 2013-04-07, 10:01:13, 597ms
computer name
: ILIE-PC
user name
: ilie <admin>
registered owner : ilie
operating system : Windows NT New build 7600
system language : English
system up time
: 3 hours 1 minute
program up time : 38 minutes 36 seconds
processor
: AMD Sempron(tm) Processor 3600+
physical memory : 686/1023 MB (free/total)
free disk space : (C:) 462.35 MB (D:) 30.15 GB
display mode
: 1280x1024, 32 bit
process id
: $4a0
allocated memory : 67.94 MB
command line
: "D:\ATI.ACE\BSplayerPro\bsplayer.exe" "D:\fylme\nevazute\Sni
tch.2013.CAM.XVID-SKA\ska-snitch-xvid.avi"
executable
: bsplayer.exe
exec. date/time : 2010-11-30 04:55
version
: 2.5.7.1049
compiled with
: Delphi 7
madExcept version : 3.0h
callstack crc
: $3216747f, $833a4c89, $833a4c89
exception number : 2
exception class : EAccessViolation
exception message : Access violation at address 0057A452 in module 'bsplayer.exe
'. Read of address 546D7104.
main thread ($a50):
0057a452 +0006 bsplayer.exe
0062b872 +0012 bsplayer.exe
006543bf +0acf bsplayer.exe
004931db +000f bsplayer.exe
004930bf +002b bsplayer.exe
0047d778 +0014 bsplayer.exe
77503573 +000a USER32.dll
00449da6 +023a bsplayer.exe
00450126 +003a bsplayer.exe
004930dd +0049 bsplayer.exe
776065c6 +0081 ntdll.dll
77606452 +000a ntdll.dll
004931db +000f bsplayer.exe
004930bf +002b bsplayer.exe
0047d778 +0014 bsplayer.exe
77503573 +000a USER32.dll
004df0a3 +0083 bsplayer.exe
004df0da +000a bsplayer.exe
004df2fa +0096 bsplayer.exe
006b3c8d +1201 bsplayer.exe

bsLabel
274 +1 TbsLabelW.SetSText2
fsfrmu
235 +1 TfsOSF.SetStatText
mbsplayu 7811 +228 TMBSPlayer.mtmrTimer
ExtCtrls
TTimer.Timer
ExtCtrls
TTimer.WndProc
Classes 31881 +0 StdWndProc
DispatchMessageA
madExcept
HandleException
madExcept
InterceptAHandleExcept
ExtCtrls
TTimer.WndProc
RtlRaiseStatus
KiUserExceptionDispatcher
ExtCtrls
TTimer.Timer
ExtCtrls
TTimer.WndProc
Classes 31881 +0 StdWndProc
DispatchMessageA
Forms
TApplication.ProcessMessage
Forms
TApplication.HandleMessage
Forms
TApplication.Run
bsplayer
653 +416 initialization

762e1192 +0010 kernel32.dll

BaseThreadInitThunk

thread $310:
77605e4a +0a ntdll.dll
NtWaitForMultipleObjects
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $628:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $160:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $e20:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $93c:
77605d6a +0a ntdll.dll
NtTraceControl
775de9bb +3c ntdll.dll
EtwpNotificationThread
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $f48:
77508fbd +26 USER32.dll
GetMessageW
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $f50:
77605e6a +0a
757b1796 +66
762deffe +3e
762defad +0d
762e1192 +10

<priority:15>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForSingleObject
WaitForSingleObjectEx
WaitForSingleObjectEx
WaitForSingleObject
BaseThreadInitThunk

thread $a34:
77508fbd +26 USER32.dll
GetMessageW
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $6c0:
77605e4a +0a
757b686c +00
762df145 +89
762df2bd +13
762e1192 +10

ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $950:
77605e6a +0a
757b1796 +66
762deffe +3e
762defad +0d
762e1192 +10

ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForSingleObject
WaitForSingleObjectEx
WaitForSingleObjectEx
WaitForSingleObject
BaseThreadInitThunk

thread $9d0:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $e1c:
77605e4a +0a
757b686c +00
762df145 +89

<priority:15>
ntdll.dll
NtWaitForMultipleObjects
KERNELBASE.dll WaitForMultipleObjectsEx
kernel32.dll
WaitForMultipleObjectsEx

762df2bd +13 kernel32.dll


762e1192 +10 kernel32.dll

WaitForMultipleObjects
BaseThreadInitThunk

thread $d78:
77508fbd +26 USER32.dll
GetMessageW
762e1192 +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 bsplayer.exe
00c30000 oldskin.dll
035e0000 FLVSplitter.ax
Splayer\Flash Video (FLV)
037c0000 wdmaud.drv
03800000 ksuser.dll
03920000 RealMediaSplitter.ax
Splayer\RealMedia splitter
039f0000 mkunicode.dll
Splayer\Haali media splitter
03a00000 AUDIOSES.DLL
04c20000 mkzlib.dll
Splayer\Haali media splitter
064c0000 bsrendv2.dll
066e0000 splitter.ax
Splayer\Haali media splitter
06770000 mkx.dll
Splayer\Haali media splitter
075b0000 ff_libfaad2.dll
Splayer\FFDShow
07640000 ffdshow.ax
Splayer\FFDShow
07e70000 NeVideo.ax
head\DSFilter
10000000 mmkeybsupp.dll
6b2e0000 ac3filter_intl.dll
Splayer\AC3 Filter
6b3e0000 ddraw.dll
6ba50000 pnrpnsp.dll
6ba70000 napinsp.dll
6bdf0000 D3DIM700.DLL
6bee0000 winrnr.dll
6bf00000 DSOUND.DLL
6c1d0000 MSVCP60.dll
6df90000 olepro32.dll
6e910000 rasadhlp.dll
6eb80000 DCIMAN32.dll
70990000 ntshrui.dll
70a00000 msi.dll
70c80000 ac3filter.ax
Splayer\AC3 Filter
70d50000 quartz.dll
70f00000 DINPUT.dll
71010000 cscui.dll
71080000 EhStorShell.dll
710c0000 ashShell.dll
710f0000 explorerframe.dll
71260000 perfos.dll
71270000 DShowRdpFilter.dll
712b0000 msdmo.dll
712c0000 devenum.dll
712e0000 CSCAPI.dll

2.5.7.1049
1.0.0.5

D:\ATI.ACE\BSplayerPro
D:\ATI.ACE\BSplayerPro\plugins
C:\Users\ilie\AppData\Roaming\B

6.1.7600.16385
6.1.7600.16385
1.0.1.2

C:\Windows\system32
C:\Windows\system32
C:\Users\ilie\AppData\Roaming\B
C:\Users\ilie\AppData\Roaming\B

6.1.7600.16385

C:\Windows\system32
C:\Users\ilie\AppData\Roaming\B

2.0.0.0
1.10.262.12

D:\ATI.ACE\BSplayerPro
C:\Users\ilie\AppData\Roaming\B
C:\Users\ilie\AppData\Roaming\B
C:\Users\ilie\AppData\Roaming\B

1.0.7.3135

C:\Users\ilie\AppData\Roaming\B

1.1.7.23

C:\Program Files\Common Files\A

1.0.0.0

D:\ATI.ACE\BSplayerPro
C:\Users\ilie\AppData\Roaming\B

6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
7.0.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
5.0.7600.16385
1.6.3.0

C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Users\ilie\AppData\Roaming\B

6.6.7600.16490
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
8.0.1483.72
6.1.7600.16385
6.1.7600.16385
1.0.0.0
6.6.7600.16385
6.6.7600.16385
6.1.7600.16385

C:\Windows\system32
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
D:\download
C:\Windows\system32
C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32

712f0000 CSCDLL.dll
6.1.7600.16385
C:\Windows\System32
71350000 wsock32.dll
6.1.7600.16385
C:\Windows\system32
71bb0000 winmm.dll
6.1.7600.16385
C:\Windows\system32
72430000 fwpuclnt.dll
6.1.7600.16385
C:\Windows\System32
72470000 winspool.drv
6.1.7600.16385
C:\Windows\system32
738a0000 msimg32.dll
6.1.7600.16385
C:\Windows\system32
73980000 WINNSI.DLL
6.1.7600.16385
C:\Windows\system32
739a0000 IPHLPAPI.DLL
6.1.7600.16385
C:\Windows\system32
73a30000 slc.dll
6.1.7600.16385
C:\Windows\system32
73af0000 NLAapi.dll
6.1.7600.16385
C:\Windows\system32
73ce0000 ntmarta.dll
6.1.7600.16385
C:\Windows\system32
73d10000 AVRT.dll
6.1.7600.16385
C:\Windows\system32
74100000 midimap.dll
6.1.7600.16385
C:\Windows\system32
74110000 MSACM32.dll
6.1.7600.16385
C:\Windows\system32
74130000 msacm32.drv
6.1.7600.16385
C:\Windows\system32
74150000 WindowsCodecs.dll
6.1.7600.16385
C:\Windows\system32
74280000 MMDevApi.dll
6.1.7600.16385
C:\Windows\System32
74310000 DUser.dll
6.1.7600.16385
C:\Windows\system32
74340000 DUI70.dll
6.1.7600.16385
C:\Windows\system32
74590000 uxtheme.dll
6.1.7600.16385
C:\Windows\system32
745d0000 propsys.dll
7.0.7600.16385
C:\Windows\system32
74710000 comctl32.dll
6.10.7600.16385
C:\Windows\WinSxS\x86_microsoft
.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
74b70000 POWRPROF.dll
6.1.7600.16385
C:\Windows\system32
74ba0000 version.dll
6.1.7600.16385
C:\Windows\system32
74c30000 wshtcpip.dll
6.1.7600.16385
C:\Windows\System32
74cf0000 dwmapi.dll
6.1.7600.16385
C:\Windows\system32
74d10000 wtsapi32.dll
6.1.7600.16385
C:\Windows\system32
74e40000 srvcli.dll
6.1.7600.16385
C:\Windows\system32
75090000 DNSAPI.dll
6.1.7600.16385
C:\Windows\system32
751d0000 mswsock.dll
6.1.7600.16385
C:\Windows\System32
755f0000 SspiCli.dll
6.1.7600.16385
C:\Windows\system32
75610000 apphelp.dll
6.1.7600.16481
C:\Windows\system32
75660000 CRYPTBASE.dll
6.1.7600.16385
C:\Windows\system32
756d0000 WINSTA.dll
6.1.7600.16385
C:\Windows\system32
75710000 profapi.dll
6.1.7600.16385
C:\Windows\system32
75780000 MSASN1.dll
6.1.7600.16415
C:\Windows\system32
75790000 DEVOBJ.dll
6.1.7600.16385
C:\Windows\system32
757b0000 KERNELBASE.dll
6.1.7600.16385
C:\Windows\system32
75800000 CFGMGR32.dll
6.1.7600.16385
C:\Windows\system32
75830000 CRYPT32.dll
6.1.7600.16385
C:\Windows\system32
759e0000 WINTRUST.dll
6.1.7600.16385
C:\Windows\system32
75a10000 NSI.dll
6.1.7600.16385
C:\Windows\system32
75a20000 comdlg32.dll
6.1.7600.16385
C:\Windows\system32
75aa0000 MSCTF.dll
6.1.7600.16385
C:\Windows\system32
75b70000 CLBCatQ.DLL
2001.12.8530.16385 C:\Windows\system32
75c30000 SHLWAPI.dll
6.1.7600.16385
C:\Windows\system32
75dd0000 GDI32.dll
6.1.7600.16385
C:\Windows\system32
75e80000 msvcrt.dll
7.0.7600.16385
C:\Windows\system32
75f30000 USP10.dll
1.626.7600.16385 C:\Windows\system32
75fd0000 LPK.dll
6.1.7600.16385
C:\Windows\system32
75fe0000 RPCRT4.dll
6.1.7600.16385
C:\Windows\system32
76290000 kernel32.dll
6.1.7600.16481
C:\Windows\system32
76470000 SHELL32.dll
6.1.7600.16385
C:\Windows\system32
770c0000 SETUPAPI.dll
6.1.7600.16385
C:\Windows\system32
77260000 advapi32.dll
6.1.7600.16385
C:\Windows\system32
77300000 oleaut32.dll
6.1.7600.16385
C:\Windows\system32
77390000 ole32.dll
6.1.7600.16385
C:\Windows\system32
774f0000 USER32.dll
6.1.7600.16385
C:\Windows\system32
775c0000 ntdll.dll
6.1.7600.16385
C:\Windows\SYSTEM32

77700000
77760000
77780000
777a0000

WS2_32.dll
IMM32.DLL
sechost.dll
WLDAP32.dll

6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385

C:\Windows\system32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Windows\system32

hardware:
+ Batteries
- Microsoft Composite Battery
+ Computer
- ACPI x86-based PC
+ Disk drives
- silicon -power USB Device
- WDC WD16 00AAJS-60PSA SCSI Disk Device
+ Display adapters
- ATI Radeon X1050
(driver 8.401.0.0)
- ATI Radeon X1050 Secondary
(driver 8.401.0.0)
+ DVD/CD-ROM drives
- ATAPI DVD A DH20A4P ATA Device
+ Floppy disk drives
- Floppy disk drive
+ Floppy drive controllers
- Standard floppy disk controller
+ Human Interface Devices
- USB Input Device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard Dual Channel PCI IDE Controller
+ Keyboards
- Standard PS/2 Keyboard
+ Mice and other pointing devices
- HID-compliant mouse
+ Modems
- LGE Mobile USB Modem (driver 4.9.4.0)
+ Monitors
- Generic PnP Monitor
+ Network adapters
- NVIDIA nForce 10/100 Mbps Ethernet (driver 73.3.5.0)
+ Portable Devices
- ADI_ILIE45
+ Ports (COM & LPT)
- Communications Port (COM1)
- LGE Mobile USB Serial Port (COM11) (driver 4.9.4.0)
- Printer Port (LPT1)
+ Processors
- AMD Sempron(tm) Processor 3600+
+ Sound, video and game controllers
- High Definition Audio Device
+ Storage controllers
- AYJFRFYY IDE Controller
- NVIDIA nForce Serial ATA Controller (driver 10.6.0.16)
- NVIDIA nForce Serial ATA Controller (driver 10.6.0.16)
+ Storage volume shadow copies
- Generic volume shadow copy
+ System devices
- ACPI Fan
- ACPI Fixed Feature Button
- ACPI Power Button
- ACPI Thermal Zone
- AMD Address Map Configuration

- AMD DRAM and HyperTransport(tm) Trace Mode Configuration


- AMD HyperTransport(tm) Configuration
- AMD Miscellaneous Configuration
- Composite Bus Enumerator
- Direct memory access controller
- Extended IO Bus
- File as Volume Driver
- High Definition Audio Controller
- High precision event timer
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Motherboard resources
- Motherboard resources
- Motherboard resources
- Numeric data processor
- NVIDIA nForce PCI System Management
- PCI bus
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard RAM Controller
- PCI standard RAM Controller
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System CMOS/real time clock
- System speaker
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Volume Manager
+ Universal Serial Bus controllers
- LGE Mobile Composite USB Device (driver 4.9.4.0)
- Standard Enhanced PCI to USB Host Controller
- Standard OpenHCD USB Host Controller
- USB Mass Storage Device
- USB Root Hub
- USB Root Hub
cpu
eax
ebx
ecx
edx
esi
edi
eip
esp
ebp

registers:
= 546d6f74
= 546d6f74
= 00000000
= 00cc9a64
= 00cc9a64
= 0012a61c
= 0057a452
= 0012a4d8
= 0012a55c

stack dump:
0012a4d8 20 5c dc 01 30 00 d0 01 - 77 b8 62 00 50 81 d6 01 .\..0...w.b.P...

0012a4e8
0012a4f8
0012a508
0012a518
0012a528
0012a538
0012a548
0012a558
0012a568
0012a578
0012a588
0012a598
0012a5a8
0012a5b8
0012a5c8
0012a5d8
0012a5e8
0012a5f8
0012a608

c4
1c
00
00
00
00
00
00
c4
1c
a0
00
12
13
13
12
3d
24
30

43
a6
00
00
00
00
00
00
30
a6
a5
00
03
01
01
03
60
00
00

65
12
00
00
00
00
00
00
49
12
12
00
0c
00
00
0c
94
00
00

00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
1f
00
00

6c
cc
00
00
00
00
00
88
34
13
7a
00
13
cd
44
13
ec
01
ff

a5
31
00
00
00
00
00
a5
a6
01
d7
00
01
ab
a6
01
a6
00
ff

12
49
00
00
00
00
00
12
12
00
47
00
00
ba
12
00
12
00
ff

00
00
00
00
00
00
00
00
00
00
00
00
00
dc
00
00
00
00
ff

0c
88
00
00
00
00
00
de
2c
00
13
cc
01
00
76
01
e4
00
ff

4d
85
00
00
00
00
00
31
4b
00
01
a5
00
00
88
00
a6
00
ff

40
df
00
00
00
00
00
49
40
00
00
12
00
00
50
00
12
00
ff

00
01
00
00
00
00
00
00
00
00
00
00
00
00
77
00
00
00
ff

5c
00
00
00
00
00
00
90
88
88
01
ef
00
1c
c8
00
10
00
1f

a5
00
00
00
00
00
00
a5
a5
85
00
86
00
a6
0f
00
92
00
88

12
00
00
00
00
00
00
12
12
df
00
50
00
12
2f
00
d9
00
50

00
00
00
00
00
00
00
00
00
01
00
77
00
00
00
00
00
00
77

.Ce.l....M@.\...
.....1I.........
................
................
................
................
................
.........1I.....
.0I.4...,K@.....
................
....z.G.........
..............Pw
................
................
....D...v.Pw../.
................
=`..............
$...............
0.............Pw

disassembling:
0057a44c
public bsLabel.TbsLabelW.SetSText2: ; function entry point
0057a44c 273 push
ebx
0057a44d
push
esi
0057a44e
mov
esi, edx
0057a450
mov
ebx, eax
0057a452 274 > cmp
byte ptr [ebx+$190], 0
0057a459
jz
loc_57a462
0057a45b
mov
eax, ebx
0057a45d
call
-$1ca ($57a298)
; bsLabel.TbsLabelW.StopScroll
0057a462 275 mov
edx, esi
0057a464
mov
eax, ebx
[...]
date/time
: 2013-04-07, 10:01:16, 593ms
computer name
: ILIE-PC
user name
: ilie <admin>
registered owner : ilie
operating system : Windows NT New build 7600
system language : English
system up time
: 3 hours 1 minute
program up time : 38 minutes 39 seconds
processor
: AMD Sempron(tm) Processor 3600+
physical memory : 686/1023 MB (free/total)
free disk space : (C:) 462.35 MB (D:) 30.15 GB
display mode
: 1280x1024, 32 bit
process id
: $4a0
allocated memory : 67.94 MB
command line
: "D:\ATI.ACE\BSplayerPro\bsplayer.exe" "D:\fylme\nevazute\Sni
tch.2013.CAM.XVID-SKA\ska-snitch-xvid.avi"
executable
: bsplayer.exe
exec. date/time : 2010-11-30 04:55
version
: 2.5.7.1049
compiled with
: Delphi 7
madExcept version : 3.0h
callstack crc
: $3216747f, $2720b63b, $2720b63b
exception number : 3
exception class : EAccessViolation
exception message : Access violation at address 0057A452 in module 'bsplayer.exe
'. Read of address 546D7104.

main thread ($a50):


0057a452 +0006 bsplayer.exe
0062b872 +0012 bsplayer.exe
006543bf +0acf bsplayer.exe
0047d778 +0014 bsplayer.exe
77503573 +000a USER32.dll
00449da6 +023a bsplayer.exe
00450126 +003a bsplayer.exe
004930dd +0049 bsplayer.exe
776065c6 +0081 ntdll.dll
77606452 +000a ntdll.dll
004931db +000f bsplayer.exe
004930bf +002b bsplayer.exe
0047d778 +0014 bsplayer.exe
77503573 +000a USER32.dll
004df0a3 +0083 bsplayer.exe
004df0da +000a bsplayer.exe
004df2fa +0096 bsplayer.exe
006b3c8d +1201 bsplayer.exe
762e1192 +0010 kernel32.dll

bsLabel
274 +1 TbsLabelW.SetSText2
fsfrmu
235 +1 TfsOSF.SetStatText
mbsplayu 7811 +228 TMBSPlayer.mtmrTimer
Classes 31881 +0 StdWndProc
DispatchMessageA
madExcept
HandleException
madExcept
InterceptAHandleExcept
ExtCtrls
TTimer.WndProc
RtlRaiseStatus
KiUserExceptionDispatcher
ExtCtrls
TTimer.Timer
ExtCtrls
TTimer.WndProc
Classes 31881 +0 StdWndProc
DispatchMessageA
Forms
TApplication.ProcessMessage
Forms
TApplication.HandleMessage
Forms
TApplication.Run
bsplayer
653 +416 initialization
BaseThreadInitThunk

thread $310:
77605e4a +0a ntdll.dll
NtWaitForMultipleObjects
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $628:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $160:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $e20:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $93c:
77605d6a +0a ntdll.dll
NtTraceControl
775de9bb +3c ntdll.dll
EtwpNotificationThread
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $f48:
77508fbd +26 USER32.dll
GetMessageW
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $f50:
77605e6a +0a
757b1796 +66
762deffe +3e
762defad +0d
762e1192 +10

<priority:15>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForSingleObject
WaitForSingleObjectEx
WaitForSingleObjectEx
WaitForSingleObject
BaseThreadInitThunk

thread $a34:
77508fbd +26 USER32.dll
GetMessageW
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $6c0:
77605e4a +0a ntdll.dll

NtWaitForMultipleObjects

757b686c
762df145
762df2bd
762e1192

+00
+89
+13
+10

KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $950:
77605e6a +0a
757b1796 +66
762deffe +3e
762defad +0d
762e1192 +10

ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForSingleObject
WaitForSingleObjectEx
WaitForSingleObjectEx
WaitForSingleObject
BaseThreadInitThunk

thread $9d0:
77605e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
762e1192 +10 kernel32.dll BaseThreadInitThunk
thread $e1c:
77605e4a +0a
757b686c +00
762df145 +89
762df2bd +13
762e1192 +10

<priority:15>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $d78:
77508fbd +26 USER32.dll
GetMessageW
762e1192 +10 kernel32.dll BaseThreadInitThunk
modules:
00400000 bsplayer.exe
00c30000 oldskin.dll
035e0000 FLVSplitter.ax
Splayer\Flash Video (FLV)
037c0000 wdmaud.drv
03800000 ksuser.dll
03920000 RealMediaSplitter.ax
Splayer\RealMedia splitter
039f0000 mkunicode.dll
Splayer\Haali media splitter
03a00000 AUDIOSES.DLL
04c20000 mkzlib.dll
Splayer\Haali media splitter
064c0000 bsrendv2.dll
066e0000 splitter.ax
Splayer\Haali media splitter
06770000 mkx.dll
Splayer\Haali media splitter
075b0000 ff_libfaad2.dll
Splayer\FFDShow
07640000 ffdshow.ax
Splayer\FFDShow
07e70000 NeVideo.ax
head\DSFilter
10000000 mmkeybsupp.dll
6b2e0000 ac3filter_intl.dll
Splayer\AC3 Filter
6b3e0000 ddraw.dll
6ba50000 pnrpnsp.dll
6ba70000 napinsp.dll
6bdf0000 D3DIM700.DLL
6bee0000 winrnr.dll

2.5.7.1049
1.0.0.5

D:\ATI.ACE\BSplayerPro
D:\ATI.ACE\BSplayerPro\plugins
C:\Users\ilie\AppData\Roaming\B

6.1.7600.16385
6.1.7600.16385
1.0.1.2

C:\Windows\system32
C:\Windows\system32
C:\Users\ilie\AppData\Roaming\B
C:\Users\ilie\AppData\Roaming\B

6.1.7600.16385

C:\Windows\system32
C:\Users\ilie\AppData\Roaming\B

2.0.0.0
1.10.262.12

D:\ATI.ACE\BSplayerPro
C:\Users\ilie\AppData\Roaming\B
C:\Users\ilie\AppData\Roaming\B
C:\Users\ilie\AppData\Roaming\B

1.0.7.3135

C:\Users\ilie\AppData\Roaming\B

1.1.7.23

C:\Program Files\Common Files\A

1.0.0.0

D:\ATI.ACE\BSplayerPro
C:\Users\ilie\AppData\Roaming\B

6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385

C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\System32

6bf00000 DSOUND.DLL
6.1.7600.16385
C:\Windows\system32
6c1d0000 MSVCP60.dll
7.0.7600.16385
C:\Windows\system32
6df90000 olepro32.dll
6.1.7600.16385
C:\Windows\system32
6e910000 rasadhlp.dll
6.1.7600.16385
C:\Windows\system32
6eb80000 DCIMAN32.dll
6.1.7600.16385
C:\Windows\system32
70990000 ntshrui.dll
6.1.7600.16385
C:\Windows\system32
70a00000 msi.dll
5.0.7600.16385
C:\Windows\system32
70c80000 ac3filter.ax
1.6.3.0
C:\Users\ilie\AppData\Roaming\B
Splayer\AC3 Filter
70d50000 quartz.dll
6.6.7600.16490
C:\Windows\system32
70f00000 DINPUT.dll
6.1.7600.16385
C:\Windows\system32
71010000 cscui.dll
6.1.7600.16385
C:\Windows\System32
71080000 EhStorShell.dll
6.1.7600.16385
C:\Windows\system32
710c0000 ashShell.dll
8.0.1483.72
D:\download
710f0000 explorerframe.dll
6.1.7600.16385
C:\Windows\system32
71260000 perfos.dll
6.1.7600.16385
C:\Windows\System32
71270000 DShowRdpFilter.dll 1.0.0.0
C:\Windows\system32
712b0000 msdmo.dll
6.6.7600.16385
C:\Windows\system32
712c0000 devenum.dll
6.6.7600.16385
C:\Windows\system32
712e0000 CSCAPI.dll
6.1.7600.16385
C:\Windows\system32
712f0000 CSCDLL.dll
6.1.7600.16385
C:\Windows\System32
71350000 wsock32.dll
6.1.7600.16385
C:\Windows\system32
71bb0000 winmm.dll
6.1.7600.16385
C:\Windows\system32
72430000 fwpuclnt.dll
6.1.7600.16385
C:\Windows\System32
72470000 winspool.drv
6.1.7600.16385
C:\Windows\system32
738a0000 msimg32.dll
6.1.7600.16385
C:\Windows\system32
73980000 WINNSI.DLL
6.1.7600.16385
C:\Windows\system32
739a0000 IPHLPAPI.DLL
6.1.7600.16385
C:\Windows\system32
73a30000 slc.dll
6.1.7600.16385
C:\Windows\system32
73af0000 NLAapi.dll
6.1.7600.16385
C:\Windows\system32
73ce0000 ntmarta.dll
6.1.7600.16385
C:\Windows\system32
73d10000 AVRT.dll
6.1.7600.16385
C:\Windows\system32
74100000 midimap.dll
6.1.7600.16385
C:\Windows\system32
74110000 MSACM32.dll
6.1.7600.16385
C:\Windows\system32
74130000 msacm32.drv
6.1.7600.16385
C:\Windows\system32
74150000 WindowsCodecs.dll
6.1.7600.16385
C:\Windows\system32
74280000 MMDevApi.dll
6.1.7600.16385
C:\Windows\System32
74310000 DUser.dll
6.1.7600.16385
C:\Windows\system32
74340000 DUI70.dll
6.1.7600.16385
C:\Windows\system32
74590000 uxtheme.dll
6.1.7600.16385
C:\Windows\system32
745d0000 propsys.dll
7.0.7600.16385
C:\Windows\system32
74710000 comctl32.dll
6.10.7600.16385
C:\Windows\WinSxS\x86_microsoft
.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
74b70000 POWRPROF.dll
6.1.7600.16385
C:\Windows\system32
74ba0000 version.dll
6.1.7600.16385
C:\Windows\system32
74c30000 wshtcpip.dll
6.1.7600.16385
C:\Windows\System32
74cf0000 dwmapi.dll
6.1.7600.16385
C:\Windows\system32
74d10000 wtsapi32.dll
6.1.7600.16385
C:\Windows\system32
74e40000 srvcli.dll
6.1.7600.16385
C:\Windows\system32
75090000 DNSAPI.dll
6.1.7600.16385
C:\Windows\system32
751d0000 mswsock.dll
6.1.7600.16385
C:\Windows\System32
755f0000 SspiCli.dll
6.1.7600.16385
C:\Windows\system32
75610000 apphelp.dll
6.1.7600.16481
C:\Windows\system32
75660000 CRYPTBASE.dll
6.1.7600.16385
C:\Windows\system32
756d0000 WINSTA.dll
6.1.7600.16385
C:\Windows\system32
75710000 profapi.dll
6.1.7600.16385
C:\Windows\system32
75780000 MSASN1.dll
6.1.7600.16415
C:\Windows\system32
75790000 DEVOBJ.dll
6.1.7600.16385
C:\Windows\system32
757b0000 KERNELBASE.dll
6.1.7600.16385
C:\Windows\system32
75800000 CFGMGR32.dll
6.1.7600.16385
C:\Windows\system32

75830000
759e0000
75a10000
75a20000
75aa0000
75b70000
75c30000
75dd0000
75e80000
75f30000
75fd0000
75fe0000
76290000
76470000
770c0000
77260000
77300000
77390000
774f0000
775c0000
77700000
77760000
77780000
777a0000

CRYPT32.dll
WINTRUST.dll
NSI.dll
comdlg32.dll
MSCTF.dll
CLBCatQ.DLL
SHLWAPI.dll
GDI32.dll
msvcrt.dll
USP10.dll
LPK.dll
RPCRT4.dll
kernel32.dll
SHELL32.dll
SETUPAPI.dll
advapi32.dll
oleaut32.dll
ole32.dll
USER32.dll
ntdll.dll
WS2_32.dll
IMM32.DLL
sechost.dll
WLDAP32.dll

6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
2001.12.8530.16385
6.1.7600.16385
6.1.7600.16385
7.0.7600.16385
1.626.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16481
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385

C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Windows\system32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Windows\system32

hardware:
+ Batteries
- Microsoft Composite Battery
+ Computer
- ACPI x86-based PC
+ Disk drives
- silicon -power USB Device
- WDC WD16 00AAJS-60PSA SCSI Disk Device
+ Display adapters
- ATI Radeon X1050
(driver 8.401.0.0)
- ATI Radeon X1050 Secondary
(driver 8.401.0.0)
+ DVD/CD-ROM drives
- ATAPI DVD A DH20A4P ATA Device
+ Floppy disk drives
- Floppy disk drive
+ Floppy drive controllers
- Standard floppy disk controller
+ Human Interface Devices
- USB Input Device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard Dual Channel PCI IDE Controller
+ Keyboards
- Standard PS/2 Keyboard
+ Mice and other pointing devices
- HID-compliant mouse
+ Modems
- LGE Mobile USB Modem (driver 4.9.4.0)
+ Monitors
- Generic PnP Monitor
+ Network adapters
- NVIDIA nForce 10/100 Mbps Ethernet (driver 73.3.5.0)
+ Portable Devices
- ADI_ILIE45

+ Ports (COM & LPT)


- Communications Port (COM1)
- LGE Mobile USB Serial Port (COM11) (driver 4.9.4.0)
- Printer Port (LPT1)
+ Processors
- AMD Sempron(tm) Processor 3600+
+ Sound, video and game controllers
- High Definition Audio Device
+ Storage controllers
- AYJFRFYY IDE Controller
- NVIDIA nForce Serial ATA Controller (driver 10.6.0.16)
- NVIDIA nForce Serial ATA Controller (driver 10.6.0.16)
+ Storage volume shadow copies
- Generic volume shadow copy
+ System devices
- ACPI Fan
- ACPI Fixed Feature Button
- ACPI Power Button
- ACPI Thermal Zone
- AMD Address Map Configuration
- AMD DRAM and HyperTransport(tm) Trace Mode Configuration
- AMD HyperTransport(tm) Configuration
- AMD Miscellaneous Configuration
- Composite Bus Enumerator
- Direct memory access controller
- Extended IO Bus
- File as Volume Driver
- High Definition Audio Controller
- High precision event timer
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Motherboard resources
- Motherboard resources
- Motherboard resources
- Numeric data processor
- NVIDIA nForce PCI System Management
- PCI bus
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard RAM Controller
- PCI standard RAM Controller
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board
- System CMOS/real time clock
- System speaker
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Volume Manager
+ Universal Serial Bus controllers

cpu
eax
ebx
ecx
edx
esi
edi
eip
esp
ebp

LGE Mobile Composite USB Device (driver 4.9.4.0)


Standard Enhanced PCI to USB Host Controller
Standard OpenHCD USB Host Controller
USB Mass Storage Device
USB Root Hub
USB Root Hub
registers:
= 546d6f74
= 546d6f74
= 00000000
= 00cc9a64
= 00cc9a64
= 00128b4c
= 0057a452
= 00128a08
= 00128a8c

stack dump:
00128a08 20
00128a18 c4
00128a28 4c
00128a38 00
00128a48 00
00128a58 00
00128a68 00
00128a78 00
00128a88 00
00128a98 c4
00128aa8 4c
00128ab8 d0
00128ac8 00
00128ad8 12
00128ae8 13
00128af8 13
00128b08 12
00128b18 0d
00128b28 24
00128b38 30

5c
43
8b
00
00
00
00
00
00
30
8b
8a
00
03
01
01
03
4d
00
00

dc
65
12
00
00
00
00
00
00
49
12
12
00
0c
00
00
0c
94
00
00

01
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
00
1f
00
00

30
9c
cc
00
00
00
00
00
b8
64
13
7a
00
13
cd
74
13
1c
01
ff

00
8a
31
00
00
00
00
00
8a
8b
01
d7
00
01
ab
8b
01
8c
00
ff

d0
12
49
00
00
00
00
00
12
12
00
47
00
00
ba
12
00
12
00
ff

01
00
00
00
00
00
00
00
00
00
00
00
00
00
dc
00
00
00
00
ff

77
0c
88
00
00
00
00
00
de
2c
00
13
fc
01
00
76
01
14
00
ff

b8
4d
85
00
00
00
00
00
31
4b
00
01
8a
00
00
88
00
8c
00
ff

62
40
df
00
00
00
00
00
49
40
00
00
12
00
00
50
00
12
00
ff

00
00
01
00
00
00
00
00
00
00
00
00
00
00
00
77
00
00
00
ff

50
8c
00
00
00
00
00
00
c0
b8
88
01
ef
00
4c
c8
00
10
00
1f

81
8a
00
00
00
00
00
00
8a
8a
85
00
86
00
8b
0f
00
92
00
88

d6
12
00
00
00
00
00
00
12
12
df
00
50
00
12
2f
00
d9
00
50

01
00
00
00
00
00
00
00
00
00
01
00
77
00
00
00
00
00
00
77

.\..0...w.b.P...
.Ce......M@.....
L....1I.........
................
................
................
................
................
.........1I.....
.0I.d...,K@.....
L...............
....z.G.........
..............Pw
................
............L...
....t...v.Pw../.
................
.M..............
$...............
0.............Pw

disassembling:
0057a44c
public bsLabel.TbsLabelW.SetSText2: ; function entry point
0057a44c 273 push
ebx
0057a44d
push
esi
0057a44e
mov
esi, edx
0057a450
mov
ebx, eax
0057a452 274 > cmp
byte ptr [ebx+$190], 0
0057a459
jz
loc_57a462
0057a45b
mov
eax, ebx
0057a45d
call
-$1ca ($57a298)
; bsLabel.TbsLabelW.StopScroll
0057a462 275 mov
edx, esi
0057a464
mov
eax, ebx
[...]
date/time
computer name
user name
registered owner
operating system
system language

:
:
:
:
:
:

2013-06-26, 09:09:05, 642ms


ILIE-PC
ilie <admin>
ilie
Windows NT New build 7600
English

system up time
: 1 hour 49 minutes
program up time : 37 seconds
processor
: AMD Sempron(tm) Processor 3600+
physical memory : 703/1023 MB (free/total)
free disk space : (C:) 104.81 MB (D:) 27.46 GB
display mode
: 1280x1024, 32 bit
process id
: $824
allocated memory : 88.92 MB
command line
: "D:\ATI.ACE\BSplayerPro\bsplayer.exe" "F:\Supernatural Seaso
n 5\Supernatural - [5x16] - Dark Side of the Moon.mkv"
executable
: bsplayer.exe
exec. date/time : 2010-11-30 04:55
version
: 2.5.7.1049
compiled with
: Delphi 7
madExcept version : 3.0h
callstack crc
: $19ca46d1, $7999c7ce, $bdc08450
count
: 3
exception number : 1
exception class : EAccessViolation
exception message : Access violation at address 005D0B5C in module 'bsplayer.exe
'. Read of address 00000058.
main thread ($1e4):
005d0b5c +0000 bsplayer.exe
ng
005cf763 +0a1b bsplayer.exe
004c6dd4 +0064 bsplayer.exe
004bc30c +001c bsplayer.exe
004bc400 +000c bsplayer.exe
004c6c3c +0188 bsplayer.exe
004c9b87 +0157 bsplayer.exe
004bc1d0 +006c bsplayer.exe
00502819 +0085 bsplayer.exe
004c6a0c +0024 bsplayer.exe
004c9cbf +0023 bsplayer.exe
004ca317 +000b bsplayer.exe
004c6c3c +0188 bsplayer.exe
004c9b87 +0157 bsplayer.exe
00502819 +0085 bsplayer.exe
004c9804 +002c bsplayer.exe
0047d778 +0014 bsplayer.exe
760143f0 +0016 USER32.dll
0050247c +0048 bsplayer.exe
0047d778 +0014 bsplayer.exe
76017690 +0044 USER32.dll
760143f0 +0016 USER32.dll
00502674 +00f0 bsplayer.exe
0047d778 +0014 bsplayer.exe
760341f4 +0016 USER32.dll
004c9c6b +00d7 bsplayer.exe
004c71dc +0010 bsplayer.exe
004c6c3c +0188 bsplayer.exe
004c9b87 +0157 bsplayer.exe
004bc1d0 +006c bsplayer.exe
00502819 +0085 bsplayer.exe
004c9804 +002c bsplayer.exe
0047d778 +0014 bsplayer.exe
760143f0 +0016 USER32.dll
0050247c +0048 bsplayer.exe
0047d778 +0014 bsplayer.exe

subshowu
subshowu
Controls
StdCtrls
StdCtrls
Controls
Controls
StdCtrls
TntControls
Controls
Controls
Controls
Controls
Controls
TntControls
Controls
Classes
TntControls
Classes
TntControls
Classes
Controls
Controls
Controls
Controls
StdCtrls
TntControls
Controls
Classes
TntControls
Classes

1028

+0 TBSPSubDownLoader.IsDownloadi

605 +188 Tsubsh.TntButton1Click


4727 +9 TControl.Click
TButton.Click
TButton.CNCommand
4667 +53 TControl.WndProc
6364 +33 TWinControl.WndProc
TButtonControl.WndProc
660 +19 TWinControlTrap.WindowProc
4574 +5 TControl.Perform
6410 +6 DoControlMsg
6596 +1 TWinControl.WMCommand
4667 +53 TControl.WndProc
6364 +33 TWinControl.WndProc
660 +19 TWinControlTrap.WindowProc
6259 +3 TWinControl.MainWndProc
31881 +0 StdWndProc
CallWindowProcW
548 +12 TWinControlTrap.Win32Proc
31881 +0 StdWndProc
SendMessageW
CallWindowProcW
599 +25 TWinControlTrap.DefWin32Proc
31881 +0 StdWndProc
CallWindowProcA
6391 +23 TWinControl.DefaultHandler
4858 +1 TControl.WMLButtonUp
4667 +53 TControl.WndProc
6364 +33 TWinControl.WndProc
TButtonControl.WndProc
660 +19 TWinControlTrap.WindowProc
6259 +3 TWinControl.MainWndProc
31881 +0 StdWndProc
CallWindowProcW
548 +12 TWinControlTrap.Win32Proc
31881 +0 StdWndProc

76013573
004df0a3
004df0da
004dbce9
005d9252
00645964
004c6c3c
004c9b87
004d8b0d
004c9804
0047d778
76013573
004df0a3
004df0da
004df2fa
006b3c8d
75dd1192

+000a
+0083
+000a
+015d
+00c6
+158c
+0188
+0157
+0421
+002c
+0014
+000a
+0083
+000a
+0096
+1201
+0010

USER32.dll
bsplayer.exe
bsplayer.exe
bsplayer.exe
bsplayer.exe
bsplayer.exe
bsplayer.exe
bsplayer.exe
bsplayer.exe
bsplayer.exe
bsplayer.exe
USER32.dll
bsplayer.exe
bsplayer.exe
bsplayer.exe
bsplayer.exe
kernel32.dll

Forms
Forms
Forms
subsu
mbsplayu
Controls
Controls
Forms
Controls
Classes
Forms
Forms
Forms
bsplayer

2803
1653
4667
6364

+21
+458
+53
+33

6259
31881

+3
+0

653 +416

DispatchMessageA
TApplication.ProcessMessage
TApplication.HandleMessage
TCustomForm.ShowModal
HandleDownloadedSubs
TMBSPlayer.msgDisp
TControl.WndProc
TWinControl.WndProc
TCustomForm.WndProc
TWinControl.MainWndProc
StdWndProc
DispatchMessageA
TApplication.ProcessMessage
TApplication.HandleMessage
TApplication.Run
initialization
BaseThreadInitThunk

thread $a44:
77105e4a +0a ntdll.dll
NtWaitForMultipleObjects
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $7a0:
77105e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $ef0:
77105e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $c64:
77105e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $d94:
77105e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $f5c:
76018fbd +26 USER32.dll
GetMessageW
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $9a4:
77105e6a +0a
752e1796 +66
75dceffe +3e
75dcefad +0d
75dd1192 +10

<priority:15>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForSingleObject
WaitForSingleObjectEx
WaitForSingleObjectEx
WaitForSingleObject
BaseThreadInitThunk

thread $eb8:
76018fbd +26 USER32.dll
GetMessageW
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $f48:
77105e4a +0a
752e686c +00
75dcf145 +89
75dcf2bd +13
75dd1192 +10

ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $ac0:
77105e4a +0a
752e686c +00
75dcf145 +89
75dcf2bd +13
75dd1192 +10

ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $a3c:
77105e4a +0a
752e686c +00
75dcf145 +89
75dcf2bd +13
75dd1192 +10

<priority:1>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $6c4:
77105e6a +0a
752e1796 +66
75dceffe +3e
75dcefad +0d
75dd1192 +10

ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForSingleObject
WaitForSingleObjectEx
WaitForSingleObjectEx
WaitForSingleObject
BaseThreadInitThunk

thread $720:
77105e7a +0a ntdll.dll
NtWaitForWorkViaWorkerFactory
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $238:
77105e4a +0a
752e686c +00
75dcf145 +89
75dcf2bd +13
75dd1192 +10

<priority:15>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $668:
77105e4a +0a
752e686c +00
75dcf145 +89
75dd1192 +10

ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
BaseThreadInitThunk

thread $d74:
77105e4a +0a
752e686c +00
75dcf145 +89
75dcf2bd +13
75dd1192 +10

<priority:15>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $df0:
77105e4a +0a
752e686c +00
75dcf145 +89
75dcf2bd +13
75dd1192 +10

<priority:15>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $bf8:
752e68a9 +00
75dcf145 +89
75dcf2bd +13
75dd1192 +10

KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $f54: <priority:1>


77105e6a +0a ntdll.dll

NtWaitForSingleObject

752e1796
75dceffe
75dcefad
76fb4013
75dd1192

+66
+3e
+0d
+10
+10

KERNELBASE.dll
kernel32.dll
kernel32.dll
ole32.dll
kernel32.dll

WaitForSingleObjectEx
WaitForSingleObjectEx
WaitForSingleObject
CoTaskMemFree
BaseThreadInitThunk

thread $f10:
76018fbd +26 USER32.dll
GetMessageW
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $de4:
76018fbd +26 USER32.dll
GetMessageW
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $770:
77105d6a +0a ntdll.dll
NtTraceControl
770de9bb +3c ntdll.dll
EtwpNotificationThread
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $dc8:
77105e4a +0a
752e686c +00
75dcf145 +89
75dcf2bd +13
75dd1192 +10

<priority:-3>
ntdll.dll
KERNELBASE.dll
kernel32.dll
kernel32.dll
kernel32.dll

NtWaitForMultipleObjects
WaitForMultipleObjectsEx
WaitForMultipleObjectsEx
WaitForMultipleObjects
BaseThreadInitThunk

thread $654: <priority:1>


771057ea +0a ntdll.dll
NtRemoveIoCompletion
75dd1192 +10 kernel32.dll BaseThreadInitThunk
thread $fd0:
77105e6a +0a
752e1796 +66
75dceffe +3e
75dcefad +0d
0052e72f +17
0047c220 +34
004053e0 +28
75dd1192 +10

ntdll.dll
NtWaitForSingleObject
KERNELBASE.dll
WaitForSingleObjectEx
kernel32.dll
WaitForSingleObjectEx
kernel32.dll
WaitForSingleObject
bsplayer.exe VirtualTrees 5154 +3 TWorkerThread.Execute
bsplayer.exe Classes
31881 +0 ThreadProc
bsplayer.exe System
ThreadWrapper
kernel32.dll
BaseThreadInitThunk

modules:
00400000 bsplayer.exe
03420000 oldskin.dll
03540000 splitter.ax
layer\Haali media splitter
035d0000 mkzlib.dll
layer\Haali media splitter
035f0000 mkunicode.dll
layer\Haali media splitter
03940000 mkx.dll
layer\Haali media splitter
04ed0000 atiumdva.dll
06290000 bsrendv2.dll
06820000 ff_libfaad2.dll
layer\FFDShow
069e0000 FLVSplitter.ax
layer\Flash Video (FLV)
074f0000 ffdshow.ax
layer\FFDShow
10000000 mmkeybsupp.dll

2.5.7.1049
1.10.262.12

D:\ATI.ACE\BSplayerPro
D:\ATI.ACE\BSplayerPro\plugins
C:\Users\ilie\AppData\Roaming\BSp
C:\Users\ilie\AppData\Roaming\BSp
C:\Users\ilie\AppData\Roaming\BSp
C:\Users\ilie\AppData\Roaming\BSp

7.14.10.163
2.0.0.0

C:\Windows\system32
D:\ATI.ACE\BSplayerPro
C:\Users\ilie\AppData\Roaming\BSp

1.0.0.5

C:\Users\ilie\AppData\Roaming\BSp

1.0.7.3135

C:\Users\ilie\AppData\Roaming\BSp

1.0.0.0

D:\ATI.ACE\BSplayerPro

6ae90000 atiumdag.dll
7.14.10.517
C:\Windows\system32
6b5d0000 ddraw.dll
6.1.7600.16385
C:\Windows\system32
6ba80000 ac3filter_intl.dll
C:\Users\ilie\AppData\Roaming\BSp
layer\AC3 Filter
6c4b0000 olepro32.dll
6.1.7600.16385
C:\Windows\system32
6f6b0000 ksuser.dll
6.1.7600.16385
C:\Windows\system32
6f6c0000 wdmaud.drv
6.1.7600.16385
C:\Windows\system32
6f700000 AUDIOSES.DLL
6.1.7600.16385
C:\Windows\system32
6f8b0000 DCIMAN32.dll
6.1.7600.16385
C:\Windows\system32
6f8c0000 libmplayer.dll
C:\Users\ilie\AppData\Roaming\BSp
layer\FFDShow
6fac0000 libavcodec.dll
C:\Users\ilie\AppData\Roaming\BSp
layer\FFDShow
70560000 DSOUND.DLL
6.1.7600.16385
C:\Windows\system32
705e0000 ac3filter.ax
1.6.3.0
C:\Users\ilie\AppData\Roaming\BSp
layer\AC3 Filter
706b0000 DINPUT.dll
6.1.7600.16385
C:\Windows\system32
706e0000 quartz.dll
6.6.7600.16490
C:\Windows\system32
70860000 napinsp.dll
6.1.7600.16385
C:\Windows\system32
70870000 winrnr.dll
6.1.7600.16385
C:\Windows\System32
70880000 CSCAPI.dll
6.1.7600.16385
C:\Windows\system32
70890000 CSCDLL.dll
6.1.7600.16385
C:\Windows\System32
708a0000 cscui.dll
6.1.7600.16385
C:\Windows\System32
70910000 EhStorShell.dll
6.1.7600.16385
C:\Windows\system32
70b70000 ntshrui.dll
6.1.7600.16385
C:\Windows\system32
70be0000 perfos.dll
6.1.7600.16385
C:\Windows\System32
70bf0000 DShowRdpFilter.dll 1.0.0.0
C:\Windows\system32
70c30000 msdmo.dll
6.6.7600.16385
C:\Windows\system32
70c40000 devenum.dll
6.6.7600.16385
C:\Windows\system32
70c60000 rasadhlp.dll
6.1.7600.16385
C:\Windows\system32
70c80000 pnrpnsp.dll
6.1.7600.16385
C:\Windows\system32
70ce0000 explorerframe.dll 6.1.7600.16385
C:\Windows\system32
710d0000 wsock32.dll
6.1.7600.16385
C:\Windows\system32
710f0000 MSACM32.dll
6.1.7600.16385
C:\Windows\system32
71350000 fwpuclnt.dll
6.1.7600.16385
C:\Windows\System32
71f10000 winspool.drv
6.1.7600.16385
C:\Windows\system32
71f90000 WINNSI.DLL
6.1.7600.16385
C:\Windows\system32
71fa0000 IPHLPAPI.DLL
6.1.7600.16385
C:\Windows\system32
73430000 winmm.dll
6.1.7600.16385
C:\Windows\system32
734d0000 msimg32.dll
6.1.7600.16385
C:\Windows\system32
73530000 slc.dll
6.1.7600.16385
C:\Windows\system32
735e0000 NLAapi.dll
6.1.7600.16385
C:\Windows\system32
737e0000 ntmarta.dll
6.1.7600.16385
C:\Windows\system32
73830000 AVRT.dll
6.1.7600.16385
C:\Windows\system32
73b10000 midimap.dll
6.1.7600.16385
C:\Windows\system32
73b20000 msacm32.drv
6.1.7600.16385
C:\Windows\system32
73b40000 WindowsCodecs.dll 6.1.7600.16385
C:\Windows\system32
73c70000 MMDevApi.dll
6.1.7600.16385
C:\Windows\System32
73d00000 DUser.dll
6.1.7600.16385
C:\Windows\system32
73d30000 DUI70.dll
6.1.7600.16385
C:\Windows\system32
73f80000 uxtheme.dll
6.1.7600.16385
C:\Windows\system32
73fc0000 propsys.dll
7.0.7600.16385
C:\Windows\system32
74100000 comctl32.dll
6.10.7600.16385
C:\Windows\WinSxS\x86_microsoft.w
indows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc
74670000 version.dll
6.1.7600.16385
C:\Windows\system32
74700000 POWRPROF.dll
6.1.7600.16385
C:\Windows\system32
74730000 wshtcpip.dll
6.1.7600.16385
C:\Windows\System32
747f0000 dwmapi.dll
6.1.7600.16385
C:\Windows\system32
74810000 wtsapi32.dll
6.1.7600.16385
C:\Windows\system32
74b10000 DNSAPI.dll
6.1.7600.16385
C:\Windows\system32

74c40000
74c50000
75060000
750f0000
75110000
75160000
751d0000
75210000
75280000
75290000
752b0000
752e0000
75330000
75450000
75510000
75520000
756c0000
75750000
75800000
75ad0000
75c20000
75ca0000
75ce0000
75d80000
75e60000
75ef0000
75ff0000
76000000
760d0000
760f0000
761a0000
76f60000
770c0000
77210000
77230000
77280000

wship6.dll
mswsock.dll
srvcli.dll
SspiCli.dll
apphelp.dll
CRYPTBASE.dll
WINSTA.dll
profapi.dll
MSASN1.dll
DEVOBJ.dll
WINTRUST.dll
KERNELBASE.dll
CRYPT32.dll
CFGMGR32.dll
LPK.dll
SETUPAPI.dll
CLBCatQ.DLL
RPCRT4.dll
MSCTF.dll
WLDAP32.dll
comdlg32.dll
WS2_32.dll
USP10.dll
kernel32.dll
oleaut32.dll
advapi32.dll
NSI.dll
USER32.dll
IMM32.DLL
msvcrt.dll
SHELL32.dll
ole32.dll
ntdll.dll
sechost.dll
GDI32.dll
SHLWAPI.dll

6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16481
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16415
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
2001.12.8530.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
1.626.7600.16385
6.1.7600.16481
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
7.0.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385
6.1.7600.16385

C:\Windows\System32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\system32
C:\Windows\SYSTEM32
C:\Windows\SYSTEM32
C:\Windows\system32
C:\Windows\system32

hardware:
+ Batteries
- Microsoft Composite Battery
+ Computer
- ACPI x86-based PC
+ Disk drives
- Kingston DT 101 G2 USB Device
- WDC WD16 00AAJS-60PSA SCSI Disk Device
+ Display adapters
- ATI Radeon X1050
(driver 8.401.0.0)
- ATI Radeon X1050 Secondary
(driver 8.401.0.0)
+ DVD/CD-ROM drives
- ATAPI DVD A DH20A4P ATA Device
+ Floppy disk drives
- Floppy disk drive
+ Floppy drive controllers
- Standard floppy disk controller
+ Human Interface Devices
- USB Input Device
+ IDE ATA/ATAPI controllers
- ATA Channel 0
- ATA Channel 1
- Standard Dual Channel PCI IDE Controller

+ Keyboards
- Standard PS/2 Keyboard
+ Mice and other pointing devices
- HID-compliant mouse
+ Modems
- LGE Mobile USB Modem #2 (driver 4.9.4.0)
+ Monitors
- Generic PnP Monitor
+ Network adapters
- NVIDIA nForce 10/100 Mbps Ethernet (driver 73.3.5.0)
+ Portable Devices
- KINGSTON
+ Ports (COM & LPT)
- Communications Port (COM1)
- LGE Mobile USB Serial Port (COM14) (driver 4.9.4.0)
- Printer Port (LPT1)
+ Processors
- AMD Sempron(tm) Processor 3600+
+ Sound, video and game controllers
- High Definition Audio Device
+ Storage controllers
- AYJFRFYY IDE Controller
- NVIDIA nForce Serial ATA Controller (driver 10.6.0.16)
- NVIDIA nForce Serial ATA Controller (driver 10.6.0.16)
+ System devices
- ACPI Fan
- ACPI Fixed Feature Button
- ACPI Power Button
- ACPI Thermal Zone
- AMD Address Map Configuration
- AMD DRAM and HyperTransport(tm) Trace Mode Configuration
- AMD HyperTransport(tm) Configuration
- AMD Miscellaneous Configuration
- Composite Bus Enumerator
- Direct memory access controller
- Extended IO Bus
- File as Volume Driver
- High Definition Audio Controller
- High precision event timer
- Microsoft ACPI-Compliant System
- Microsoft System Management BIOS Driver
- Microsoft Virtual Drive Enumerator Driver
- Motherboard resources
- Motherboard resources
- Motherboard resources
- Numeric data processor
- NVIDIA nForce PCI System Management
- PCI bus
- PCI standard ISA bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard PCI-to-PCI bridge
- PCI standard RAM Controller
- PCI standard RAM Controller
- Plug and Play Software Device Enumerator
- Printer Port Logical Interface
- Programmable interrupt controller
- Remote Desktop Device Redirector Bus
- System board

- System CMOS/real time clock


- System speaker
- System timer
- Terminal Server Keyboard Driver
- Terminal Server Mouse Driver
- UMBus Enumerator
- UMBus Enumerator
- UMBus Root Bus Enumerator
- Volume Manager
+ Universal Serial Bus controllers
- LGE Mobile Composite USB Device (driver 4.9.4.0)
- Standard Enhanced PCI to USB Host Controller
- Standard OpenHCD USB Host Controller
- USB Mass Storage Device
- USB Root Hub
- USB Root Hub
cpu
eax
ebx
ecx
edx
esi
edi
eip
esp
ebp

registers:
= 00000000
= 01d30030
= 00000064
= 760189d3
= 0000000a
= 0012ee7c
= 005d0b5c
= 0012ec40
= 0012ecf0

stack dump:
0012ec40 68
0012ec50 7c
0012ec60 0f
0012ec70 3c
0012ec80 00
0012ec90 1f
0012eca0 00
0012ecb0 00
0012ecc0 8d
0012ecd0 00
0012ece0 04
0012ecf0 30
0012ed00 7c
0012ed10 7c
0012ed20 f0
0012ed30 20
0012ed40 4d
0012ed50 49
0012ed60 00
0012ed70 c8

f7
ee
88
ed
00
88
00
00
88
00
00
ee
ee
ee
67
1d
d7
21
00
ed

5c
12
01
12
00
01
00
00
01
00
00
12
12
12
24
df
0d
11
00
12

00
00
76
00
00
76
00
00
76
00
00
00
00
00
00
01
77
77
00
00

0c
f0
00
24
70
c9
00
e3
03
90
00
da
05
7c
1c
c8
1b
34
15
15

f0
c2
00
00
00
88
00
62
00
3d
00
6d
c4
ee
69
ec
7b
ee
02
02

12
4b
00
00
00
01
00
06
00
e5
00
4c
4b
12
24
12
6c
12
00
00

00
00
00
00
00
76
00
76
00
01
00
00
00
00
00
00
00
00
00
00

0c
a0
15
01
ff
c0
64
00
97
a8
00
a0
a0
a0
20
7a
fe
3c
cd
88

4d
60
02
00
ff
ec
ec
00
84
42
00
60
60
60
4d
d7
ff
ee
ab
ed

40
df
00
00
ff
12
12
00
6f
e4
00
df
df
df
2b
47
ff
12
ba
12

00
01
00
00
ff
00
00
00
77
01
00
01
01
01
00
00
ff
00
dc
00

f0
3c
2b
00
ff
01
8d
c0
34
03
c0
11
3f
f8
f0
00
ae
00
00
a4

ec
1f
f8
00
ff
00
88
77
ee
00
e7
c3
6c
17
6d
ee
22
00
00
ed

12
26
12
00
ff
00
01
e0
12
00
d6
4b
4c
27
24
12
11
00
00
12

00
00
74
00
ff
00
76
01
00
00
01
00
00
00
00
00
77
00
00
00

h.\......M@.....
|.....K..`..<.&.
...v........+..t
<...$...........
....p...........
...v...v........
........d......v
.....b.v.....w..
...v......ow4...
.....=...B......
................
0....mL..`....K.
|.....K..`..?lL.
|...|....`....'.
.g$..i$..M+..m$.
........z.G.....
M..w.{l......".w
I!.w4...<.......
................
................

disassembling:
005d0b5c
public subshowu.TBSPSubDownLoader.IsDownloading: ; function entry
point
005d0b5c 1028 > mov
al, [eax+$58]
005d0b5f 1029 ret

You might also like